THE STRATEGY 1. Establishing a Resilient cyber ecosystem in Afghanistan a) Information Systems Security Directorate (ISSD) of Ministry of Communications and Information Technologies (MCIT) to coordinate all cyber and information security related issues in the country with clearly defined roles and responsibilities. Having had the privilege of managing AFCERT since its establishment, ISSD should become an independent entity within Government structure once it reaches its maturity levels. This will avoid every kind of unwanted and unwarranted influence from other government and nongovernment entities on cybersecurity tasks and decisions ensuring ISSD’s full integrity. b) Encourage both public and private sector to assign a member of senior management as Chief Security Officer (CSO), giving them the responsibility of cybersecurity efforts and initiatives in the country, ensuring public private partnership. c) Encourage both public and private sectors to draft and develop their information security policies aligned with their business profile and services in compliance with international standards and best practices. Policies should be comprehensive, up to date with various data security methodologies, include Disaster Recovery Plan and business continuity. d) Both public and private sectors to dedicate budget for cyber and information security activities and initiatives. The budget should be for the overall cybersecurity initiatives including IT infrastructure protection mechanisms, licensed software, patches and capacity building for IT personnel. e) AFCERT to serve both public and private sectors as a first responder to cyber and computer incidents, given its professional staff and good reputation AFCERT will also work together with both sectors in order to establish mini and provincial CERTs for better coordination of the cybersecurity agenda, AFCERT will make sure that all entities adapt to and abide by the AFCERT assigned procedures and best practices in the field of incident response, cyber/computer crime scene data collection. f) MCIT from security point of view will certify and approve any IT related procurement within the government, MCIT will come up with new guidelines and policies for the webhosting companies, software developers and IT services provider. 2. Establishing a framework for information safety, assurance, information security policies a) ISSD of MCIT should enforce the adaptation of international standards, information security best practices, and compliance in order to ensure Confidentiality, Accessibility and Integrity of information throughout government networks. Information  Systems  Security  Directorate  -­‐  MCIT  

Select target paragraph3